Bug 2529295 (CVE-2026-86330) - CVE-2026-86330 noobaa-core: noobaa-core: OS command injection in cluster_internal_api.set_hostname_internal
Summary: CVE-2026-86330 noobaa-core: noobaa-core: OS command injection in cluster_inte...
Keywords:
Status: NEW
Alias: CVE-2026-86330
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-07 07:21 UTC by OSIDB Bzimport
Modified: 2026-09-28 11:56 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-07 07:21:17 UTC
An OS command injection vulnerability exists in noobaa-core within the src/util/os_utils.js file. The set_hostname function uses a template literal to interpolate the hostname parameter directly into a shell command executed via exec(). Because the input is not sanitized, an attacker can use shell metacharacters (e.g., semicolons or backticks) to execute arbitrary commands. This endpoint is exposed via the cluster_internal_api.set_hostname_internal RPC method. Exploitation requires a valid administrative auth_token. A successful attack allows for arbitrary command execution as the noob user (UID 10001) within the container, which can lead to full container compromise.


Note You need to log in before you can comment on or make changes to this bug.